Impact
The vulnerability in Oracle Helidon, specifically in the Imperative Web Server component, affects versions 4.0.0 through 4.5.0. It allows unauthenticated HTTP requests to read a subset of Helidon accessible data. The flaw is categorized as CWE‑284, Improper Access Control. An attacker with network access can exploit it to obtain confidential data without credentials. The CVSS 3.1 base score of 5.3 indicates a moderate impact focused on confidentiality with no effect on integrity or availability.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.5.0 are affected. No other versions or products are currently identified as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the medium severity range. EPSS score is < 1 % and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker can exploit this from any network location with HTTP access to the Helidon service. No special privileges or additional conditions are required for exploitation.
OpenCVE Enrichment